Skip to main content

CWE archive

CWE-502 CVEs

Programmatic archive

3,023 CVEs tagged with CWE-5021,168 Critical, 1,450 High, 333 Medium, 72 Low, 0 Unrated.

CVE-2026-34993

Published Jun 2, 2026

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code e…

CVSS 6.4 · Medium
evidence mentions
15
Buzz score
40.7
Vendor/product tagsBeta · best-effort

CVE-2026-24237

Published Jun 2, 2026

NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code e…

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-24221

Published Jun 2, 2026

NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code e…

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-39555

Published Jun 2, 2026

Deserialization of Untrusted Data vulnerability in Elated-Themes Askka allows Object Injection. This issue affects Askka: from n/a through 1.3.1.

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-39551

Published Jun 2, 2026

Deserialization of Untrusted Data vulnerability in Elated-Themes Töbel allows Object Injection. This issue affects Töbel: from n/a through 1.8.1.

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-39550

Published Jun 2, 2026

Deserialization of Untrusted Data vulnerability in Elated-Themes Aperitif allows Object Injection. This issue affects Aperitif: from n/a through 1.6.

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-10566

Published Jun 2, 2026

A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipul…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-9330

Published Jun 1, 2026

IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component. This…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-9319

Published Jun 1, 2026

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security.

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49121

Published Jun 1, 2026

AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the MessageQueue.recv() function within shm_broadcast.py that a…

CVSS 9.2 · Critical
evidence mentions
6
Buzz score
38.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-38950

Published Jun 1, 2026

An issue in ESA AnomalyMatch before 1.3.1 allow attackers to execute arbitrary code via crafted model checkpoint files. The affected components load model files from session direc…

CVSS 7.8 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-10532

Published Jun 1, 2026

Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily rest…

CVSS 2.9 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-7858

Published Jun 1, 2026

A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA Mag…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-45360

Published Jun 1, 2026

Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomReference.deserialize_reference`) imported and dispatched arbitrary class paths drawn from DAG-author-…

CVSS 7.3 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-42359

Published Jun 1, 2026

A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authenticated UI/API user with XCom write permission on a Dag to set XCom entries under…

CVSS 8.8 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-10042

Published May 29, 2026

manga-image-translator contains a remote code execution vulnerability in the shared API server mode due to unsafe deserialization of untrusted pickle data in the share.py module,…

CVSS 9.2 · Critical
evidence mentions
4
Buzz score
22.6

CVE-2025-11993

Published May 29, 2026

The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8 via the 'settings' paramet…

CVSS 8.8 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-9828

Published May 28, 2026

Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restr…

CVSS 2.9 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-37579

Published May 28, 2026

An issue in SMSGate sms-core<=2.1.13.6 allows a remote attacker to execute arbitrary code via the Cmpp7FDeliverRequestMessageCodec.java component

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-47161

Published May 27, 2026

RELATE is a web-based courseware package. Prior to commit d66ba5659b459bf1ba56b7109b5f9ecf197cbefb, RELATE LMS configures its Celery workers to accept and deserialize untrusted 'p…

CVSS 8.7 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-45134

Published May 27, 2026

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-48919

Published May 27, 2026

Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation.

CVSS 6.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48917

Published May 27, 2026

Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation.

CVSS 6.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44843

Published May 26, 2026

LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-24162

Published May 26, 2026

NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability mig…

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort
Showing 326-350 of 3,023 CVEsPage 14 of 121